What I've found to be helpful to me was using EDUCAUSE's Information Security Governance Assessment Tool as a template alongside ISACA's "COBIT Mapping ISO/IEC 17799 :2000 With COBIT" http://www.isaca.org/ContentManagement/ ... ntID=35228 into my own template worked wonders in mapping most standards and guidelines. (You need to be an ISACA member to download that file). I went through a few months in meshing those two into something I use (sorry its work related so I can't and won't post).

EDUCAUSE has some great material there in regards to HIPPA (http://net.educause.edu/ir/library/excel/EAF0507d.xls) which would obviously need to be customized. For anyone who've done any GRC work, one would know it is a broad (to me - boring) process. I found it best to make my own template since there is so much overlap.

Dengar13: That linked Risk Assessment Report is ok, rather on the basic side, I implore you to check out the EDUCAUSE link as it encompasses a more complete and thorough walkthrough across all fields of compliance (technical and nontechnical) however, as stated, you'd need to spend time conforming it to your own business.

Most of these are generic Information Technology Risk Assessment documents. If you need a good resource for the HIPAA Security Risk Analysis which includes assessment for Administrative safeguards, Physical safeguards and Technical safeguards, then check this http://www.training-hipaa.net/template_ ... .htm&nbsp;

Normally companies charge anywhere between 10K to 20K for doing this type of assessment. I would recommend that before you start the assessment go through comprehensive training like Certified HIPAA Privacy Security Expert (CHPSE) as it looks like are very much involved in your HIPAA compliance. Comprehensive training will help you understand what you need, why you need etc. After having clear understanding of HIPAA regulation, it is easy to do the risk assessment.

The network vulnerability assessment (Pen testing) is something that you will have to do it on your own.